Publication Date: 2022-06-21
Last Update: 2022-06-21
Current Version: V1.0
CVSS v3.1 Base Score: 9.8

Affected Product and Versions Remediation
SIMATIC WinCC OA V3.16:
All versions in default configuration
Enable server-side authentication (SSA) or Kerberos authentication for your WinCC OA project
https://www.winccoa.com/downloads/detail/security-guideline-wincc-oa-v316-1.html
SIMATIC WinCC OA V3.17:
All versions in non-default configuration
Ensure that server-side authentication (SSA) is enabled for your WinCC OA project (which is the default configuration); alternatively enable Kerberos authentication
https://www.winccoa.com/downloads/detail/security-guideline-wincc-oa-v317.html
SIMATIC WinCC OA V3.18:
All versions in non-default configuration
Ensure that server-side authentication (SSA) is enabled for your WinCC OA project (which is the default configuration); alternatively enable Kerberos authentication
https://www.winccoa.com/downloads/detail/security-guideline-wincc-oa-v318.html

CVSS v3.1 Base Score 9.8
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-603: Use of Client-Side Authentication

https://www.siemens.com/cert/advisories